John the Ripper tests password hashes against wordlists and rules. It is used to audit your own systems for weak passwords (for example, finding guessable passwords in a directory export before an attacker does).
Only run it against hashes you are authorised to test.
# Combine passwd and shadow (root) into a single file John understands
sudo unshadow /etc/passwd /etc/shadow > hashes.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt # dictionary attack
john --show hashes.txt # display cracked passwords
john --list=formats | tr ',' '\n' | head # supported hash types
Passwords that fall to a dictionary attack in seconds should be reset, and the underlying cause fixed (length and passphrase policy, multi-factor authentication, or a password manager such as pass). Delete the hash files when you are done.